Wbce Cms
Vendor:
First CVE: Apr 28, 2017 · Active for 9 years
40
Total CVEs
More Total CVEs than 97% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wbce Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2017
9 years ago
Most Recent CVE
Jan 13, 2026
192 days ago
CVE Severity & Scoring
Wbce Cms40 CVEs
53%
38%
10%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.0%)
Network38 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (97.5%)
High1 (2.5%)
Unknown0 (0.0%)
User Interaction
None17 (42.5%)
Unknown0 (0.0%)
Required23 (57.5%)
Privileges Required
Low15 (37.5%)
High13 (32.5%)
None12 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3817CRITICAL wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | Dec 9, 2021 | 9.8 | 65 | NO | YES |
CVE-2022-46020CRITICAL WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | Dec 20, 2022 | 9.8 | 64 | NO | YES |
CVE-2023-39796CRITICAL SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter. | Nov 10, 2023 | 9.8 | 41 | NO | YES |
CVE-2025-67504CRITICAL WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secu | Dec 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-50936HIGH WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attac | Jan 13, 2026 | 8.8 | 31 | NO | NO |
CVE-2022-45038MEDIUM A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected i | Nov 25, 2022 | 5.4 | 29 | NO | YES |
CVE-2025-34506HIGH WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a special | Dec 11, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-58283HIGH WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers | Dec 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-65094HIGH WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the gro | Nov 19, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-30073MEDIUM WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. | May 17, 2022 | 5.4 | 28 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
2.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Wbce Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.2 | 1 | 8.8 | 0.6% | 0 | 0 |
| 1.6.1 | 5 | 5.9 | 0.3% | 0 | 0 |
| 1.6.0 | 1 | 9.8 | 6.1% | 0 | 1 |
| 1.5.4 | 6 | 6.4 | 7.2% | 0 | 3 |
| 1.5.3 | 1 | 7.2 | 1.3% | 0 | 0 |
| 1.5.2 | 6 | 6.9 | 1.1% | 0 | 1 |
| 1.3.1 | 1 | 4.8 | 0.6% | 0 | 0 |
| 1.1.11 | 1 | 4.8 | 0.6% | 0 | 0 |